What we collect, and why.
Kova Studio is a one-person studio. There is no marketing department and no data being quietly resold. This page says plainly what happens to your information — including what happens if we contacted you first, which is the part most privacy policies skip.
The short version
- If you fill in the form
- We use your details to answer you and prepare your diagnosis. Nothing else.
- If we emailed you first
- We found you through public business sources — never the KBO register — and one reply removes you permanently.
- Analytics
- No cookies, no profiles, no ad networks. Visit counts only.
- Selling your data
- Never. Not to anyone, for any price.
Who is responsible
The controller for the data described on this page is:
Kova Studio
Operated by [LEGAL NAME]
[STREET AND NUMBER], [POSTCODE AND MUNICIPALITY], Belgium
Enterprise number (KBO/BCE): BE 0XXX.XXX.XXX
hello@kovastudio.be
Kova Studio is not required to appoint a Data Protection Officer, and has not appointed one. Questions about anything on this page go to hello@kovastudio.be and are answered by the person who runs the studio.
Full company identification is on the legal information page.
When you contact us
This covers the booking form at the bottom of the homepage and any email you send us.
What we collect
- From the form: your business name or website, which area is pinching (quotes, hours, risk, revenue), and the email address or phone number you give us.
- From email: whatever you choose to write, plus your email address and the technical headers your mail client sends.
The form asks for three things because three is what a first conversation needs. There is no hidden field collecting anything else.
Why, and on what legal basis
To reply to you, to hold the free 20-minute call, and to prepare the written diagnosis you asked for. The legal basis is Article 6(1)(b) GDPR — steps taken at your request before entering a contract. If nothing comes of it, that is fine; the basis still covers the conversation.
How long we keep it
If no work follows, 12 months from our last exchange, then deleted. If we do work together, the records that Belgian accounting law requires us to keep are held for 7 years; the rest is deleted on the same 12-month rule.
When we contact you
If you received an email from us that you did not ask for, this section is the one that matters — and under Article 14 GDPR you are entitled to all of it.
What we hold
- Your business name, sector and region
- A general business email address (
info@,contact@or similar) - Your website address, and notes we made from reading it
Where we got it
From your own public website, or a public professional directory. Every email we send names the specific source in its footer, so you never have to guess.
Not from the KBO/BCE register. Belgian law prohibits reusing the enterprise register for direct marketing, and we do not do it. We do consult the register for one narrow purpose: checking a company's legal form, so that we only ever contact incorporated companies at impersonal addresses, as the Royal Decree of 4 April 2003 requires. That check is not marketing use of the register, and no contact details are taken from it.
Why, and on what legal basis
To offer a diagnostic service we believe is relevant to your business. The legal basis is Article 6(1)(f) GDPR — our legitimate interest in reaching businesses that may need the work — exercised strictly within the exception in the Royal Decree of 4 April 2003 for legal persons contacted at impersonal addresses. We have carried out and documented a balancing test for this. We do not send unsolicited email to sole traders or to named personal addresses.
Saying no — and what we owe you when you do
You have an absolute right to object to direct marketing under Article 21(2) GDPR. No reason needed, and no consequence.
- Reply STOP to any email, or write to hello@kovastudio.be
- We confirm it by email within 48 hours, and that confirmation contains no advertising
- Your address goes on a suppression list so that you are never contacted again
The suppression list is the one thing we keep indefinitely — keeping it is the only way to keep the promise. It holds the minimum needed to recognise you and nothing more.
How long we keep it
12 months from the last meaningful contact, then deleted. Prospect data is held for a shorter period than client data, deliberately.
When you read this site
We use GoatCounter, a small analytics tool, served from our own domain so it works even with an ad blocker running.
What it records
- Which page was viewed, and which page or link referred you
- Browser, operating system, screen size and country
- A handful of events we set ourselves: a button clicked, a demo opened, how far down the page you got
What it does not do
It sets no cookies, writes nothing to your device, and builds no profile of you. To avoid counting one person twice it derives a short-lived salted hash from your IP address and browser; the IP address itself is not stored, and the hash cannot be traced back to you. There is no advertising network involved and no data leaves this arrangement.
Because nothing is stored on or read from your device, no cookie banner is required. The legal basis is Article 6(1)(f) — our legitimate interest in knowing whether the site works. If you would rather not be counted at all, any content blocker or your browser's Do Not Track setting will do it, and nothing on the site will break.
What is retained is aggregate statistics — visit counts by page and by day — not records about individuals.
Who else touches your data
Three suppliers, each doing one job:
Netlify — hosts the website and receives booking form submissions.
Google Workspace — our email, so any message you send us is stored there.
GoatCounter — the analytics counts described above.
Netlify and Google are US-headquartered, so some data may be processed outside the European Economic Area. Those transfers rely on the EU–US Data Privacy Framework and, where applicable, the European Commission's Standard Contractual Clauses. Ask us and we will point you to the current safeguards.
Beyond these three, nobody. We do not sell, rent, trade or share your data with advertisers, data brokers or lead-generation companies. If we are ever legally compelled to hand something over, we will tell you unless the law forbids it.
Your rights
Under the GDPR you can ask us to:
- Show you what we hold about you (access)
- Correct anything wrong (rectification)
- Delete it (erasure)
- Pause our use of it while something is disputed (restriction)
- Hand it over in a portable format (portability)
- Stop — object to processing, absolutely so for direct marketing
- Withdraw consent where consent was the basis, without affecting what came before
Write to hello@kovastudio.be. We answer within one month, usually far sooner, and it costs you nothing. We may ask a question to confirm who you are — only to avoid handing your data to someone else.
If we get it wrong, tell us and we will fix it. You can also complain to the Belgian Data Protection Authority at any point, without going through us first.
No decisions here are made by automated processing or profiling.
Security
The site is served over HTTPS. Access to the form submissions and the mailbox is protected by strong, unique credentials and two-factor authentication. Data is kept only as long as the periods above allow, on the principle that the safest record is the one no longer held.
No system is perfect. If a breach ever put your rights at real risk, we would notify the supervisory authority within 72 hours and tell you directly where the law requires it.
Changes to this page
If what we do changes, this page changes with it, and the date at the top moves. We keep no separate archive of old versions; if you need to know what it said on a given date, ask and we will tell you.